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communications network 

^ The present invention discloses an apparatus 
^ and method for transmitting a data Packet over 
a wrireless network witii improved secunty. tacn 
transmitted message includes three seg^ente^ 
A firet segment includes infonnation 'dentifymg 
the originator of the message. A seOTnd seg- 
ment includes a digital signature obtained by 
Sng and encrypting the ^ata to be transrrut- 
ted A third segment includes the data packet 
Upon receiving the message, a wireless receiv- 
ing unit uses the information contained in the 
firit segment to retrieve an encrypbon key and. 
thereby, identify the originator of the message. 
The wireless receiving unit then hashes^and 
encrypts the received data pack^ ^^^^^'^S *° 
the same hashing and encryption^ algonthms 
used to fom the digital signature The resulting 
encrypted hashed version of the data packet s 
Sared to the received digital signature in 
3 to establish the integrity of the received 
data packet 
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FIELD OF THE INVENTION 



The present invention relates generally to com- 
munication systems that transmit information via a 
wireless network. More particularly, the present in- 
vention relates to user-Identification and the verifica- 
tion of data integrity in wireless communication sys- 
tems. ' 

BACKGROtJND OF THP INVENTION 

As communication over multiple access media 
such as wireless networks, has become increasingly 
popular, the security concerns and risks associated 
with such communication systems also have in- 
creased. Wireless communication systems, for exam- 
ple, pose unique security concerns compared to the 
security risks associated with vrired or tethered sys- 
tems. Communication over wireless networks Is more 
vulnerable to attack by unauthorized persons using 
the system in any of a number of ways. Transmission 
Of data in the clear, for example, means that the data 
can be monitored or intercepted easily by anyone 
possessing an appropriate receiver. Similarly, trans- 
mission of a user's identification in the clear opens 
the user to traffic analysis. 

Many other threats and vulnerabilities are asso- 
ciated with wireless communication. For example 
wireless systems are vulnerable to misuse of resourc^ 
es associated with the system, such as the cloning of 
wireless communication devices by persons who are 
not subscribers to the network's services. The cloned 
devices can be programmed to Include identification 
rnformation associated with a legitimate subscriber or 
the subscriber's device. Such techniques allow the 
non-subscriber to qualify for service in a fraudulent 
manner, which may result in unrecoverable costs to 
the service provider. 

Yet another security concern pertaining to the 
use of wireless systems, involves one person's trans- 
mitting information and denying that the information 
was sent or attributing the transmission to another 
subscriber. This problem is of particular concern to 
anyone wishing to transact business using wireless 
communication systems. Furthermore, if business 
dealings are to be transacted using wireless systems 
the parties to the transactfon must be assured that 
the integrity of the data is preserved. 

The security issues mentioned above, among 
others, suggest the need for efficient and cost- 
effective authentication and verification techniques 
for use in wireless communication systems. 



ferably comprises a wireless transmitting unit for 
transmitting a message via a wireless networic where 
the message comprises a first segment including 
Identification infomnation. a second segment includ- 
s ing a data packet, and a third segment including a dig- 
ital signature. The digital signature is obtained by ap- 
plying a hashing algorithm and an encryption algo- 
nthm to the data packet, where the encryption alg(v 
nthm uses an encryption key corresponding to the 
*o Identification information. The system further com- 
pnses a wireless network and a wireless receiving 
unit. The wireless receiving unit may comprise circui- 
try for receiving the message and a memory unit for 
storing the encryption key corresponding to the iden- 
»5 tif ication Information. The wireless receiving unit also 
has a hashing unit for hashing the data packetaccord- 
ing to the hashing algorithm to form hashed data and 
an encryption unit for forming encrypted hashed data 
by applying the encryption algorithm to the hashed 
20 data using the encryption key. In addition, the wire- 
less receiving unit may include a comparing unit for 
comparing the encrypted hashed data to the digital 
signature and a processor for controlling the flow of 
data between other units in the wireless receivinq 
25 unit. " 

Other features and advantages of the present in- 
vention will be apparent by reference to the following 
detailed description and accompanying drawings. 

^0 BRIEF DESCRIPTION OF THE DRAWIMRs 

FIG. 1 illustrates an exemplary wireless commu- 
nication system according to the present invention. 

FIG. 2 shows a signed message having three 
35 segments in accordance with the present inventton. 

FIG. 3 IS a flow chart showing the steps for iden- 
tifying and authenticating the originator of a transmis- 
sion and verifying the integrity of the transmission ac- 
cording to the method of the present invention 

40 

DETAILED DESCRIPTIO N OF THE INVENTIOM 



SUMMARY OF THE INVENTION 

The present invention discloses a system for 
transmitting information over a wireless communica- 
tion system with improved security. This system pre- 



FIG. 1 1llustrates an exemplary wireless commu- 
nication system 1 according to the present invention 
*5 The wireless system 1 includes a messaging networic 
100 which serves as a platform for end-user services 
such as exchanging messages or mediating transac- 
tions between subscribers. Each such subscriber will 
typically have a wireless device such as wireless de- 
50 vice 150. As a result, the messaging network 100 will 
typically communicate with a large number of wireless 
devices even though FIG. 1 shows a single such de- 
vice 150 forsimplicity of presentation. A system com- 
ponent, such as the wireless device 150, which trans- 
55 mits information via a wireless communication net- 
work generally may be referred to as a wireless trans- 
mitting unit 

Information is transferred to and from the mes- 
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saging network 100 via a wireless interface 130 ao 
cording to a specified protocol. In FIG. 1 , the messag- 
ing network 100 may be connected, for example, by 
an Ethernet format connection to the wireless inter- 
face 130. which serves as an interface between the 
messaging network 100 and a wireless network 140. 
A system component, such as the messaging network 
100» which receives information via a wireless net- 
work, may generally be referred to as a vwreless re- 
ceiving unit. The wireless network 140 may suitably 
be a public packet radio network such as the RAM 
Mobile Data Network, the ARDIS Network, or any 
Cellular Digital Packet Data (CDPD) network. 

In the system 1, the transfer of information be- 
tween the wireless interface 130 and the wireless 
network 140 occurs in either a connectionless or con- 
nection-oriented manner. The transfer of information 
between the wireless network 140 and the wireless 
device 150 takes place In a connectionless manner 
according to a protocol specified by the particular 
wireless network 140. A connectionless transfer of in- 
formation may be distinguished from a session-ori- 
ented approach in which a "handshake" routine typi- 
cally takes place between the network and a user of 
or subscriber to the network. The handshake routine 
typically requires that the user be authenticated as le- 
gitimate at the beginning of a session, for example, by 
using a personal password that identifies the user. 
The user then sends messages, for example, to the 
network, after which the session is terminated. In a 
session-oriented approach. Individual nnessages are 
not verified or authenticated. In contrast, a connec- 
tionless approach does not require that communica- 
tion between the user and network be initialized and 
terminated at some later time. Rather, the connec- 
tionless approach allows individual packets of Infor- 
mation or data, which are self-contained, to be sent to 
the network without prior negotiation and without pri- 
or confirmation of the user with the exception of a 
possible subscription agreement penmitting the sub- 
scriber to use the network. 

In FIG. 1, the wireless device 150 may be a per- 
sonal digital assistant (PDA) or personal communica- 
tor, or a device for use in a cellular telephone system, 
such as a digital cellular telephone. It is to be under- 
stood, however, that any device that Is capable of 
transmitting and receiving appropriate signals over a 
wireless network may be used. In the discussion that 
follows, it will be assumed that the device 150 is a 
PDA having an data entry unit 160, such as a key- 
board, keypad, stylus, or any other suitable means for 
entering data. 

In accordance with the present invention, each 
wireless device intended for use in the system 1, such 
as the wireless device 1 50. is assigned a unique iden- 
tifier or identification information. The identification 
information is stored in the device 150. for example, 
as an electronic serial number (ESN) 171 incorporat- 



ed into the device 1 50 at the time of manufacture. By 
way of example, the ESN 171 may be stored in a 
memory unit 170. Alternatively, the identification in- 
formation may be a user name, an account identif ica- 
5 tion. an account name, or a service identification stor- 
ed in the memory unit 170. Additionally, each sub- 
scriber to the messaging network's services is provid- 
ed with a unique private encryption key, K, for use as 
explained below. The encryption key. K. is one that 
10 can be used with a secure encryption scheme. The 
key, K, may be, for example, a 55.bit Data Encryption 
Standard (DES) key for use in a cryptosystem such 
as the one described in "Data Encryption Standards," 
Federal Information Processing Standard, Publica- 
ns tion No. 46, National Bureau of Standards. January 
1977. The private key. K, is entered into the device 
1 50, preferably in a manner not subject to tampering, 
and'is stored for further use in a file 172 in the mem- 
ory unit 170. The private key may be periodically up- 
20 dated to further increase its security. The private key. 
K, is intended for the private use of the subscriber 
alone and should not be disclosed to other individ- 
uals. 

In the wireless system 1 , the messaging networK 
25 1 00 and the wireless device 150 each follow a mes- 
sage-oriented protocol, which resides on the messag- 
ing network 100 and the wireless device 150 in a re- 
ceiver 105 and a transmitter 155. respectively. Both 
the receiver 105 and the transmitter 1 55 may suitably 
30 be. for example, a radio transceiver connected to a 
modem. 

As indicated by FIG. 2. which shows an exem- 
plary message 200, each message transmitted by 
the wireless device 150 preferably contains three 
35 segments. A first segment 201 includes the identifi- 
cation information that is retrieved from the memory 
unit 170 by the device 150. for example the electronic 
serial number 1 71 . A second segment 203 includes a 
data packet that the subscriber wishes to send. Final- 
40 ly. a third segment 202 includes a digital signature as 
further explained below. A message, such as the 
message 200, containing the three segments 201. 
202 and 203. may be referred to as a signed mes- 
sage. 

45 FIG. 3 is a flow chart showing the steps of send- 

ing a message according to the method of the present 
invention. When the subscriber wishes to send a mes- 
sage via the wireless network 140 using the wireless 
device 150, the subscriber enters the message data 
50 into the device 150 as shown in step 300 of FIG. 3. 
The message data may be entered into the device 
150 by using the data entry unit 160 associated with 
the device 150. For example, the subscriber could en- 
ter the data into the device 150 by using a keypad. 
55 Once the subscriber enters the message data 

that he wishes to transmit, a processor 162, such as 
a central processing unit, connected to the data entry 
unit 160 and to the transmitter 155, disassembles the 
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data into smaller data packets, as shown in step 302 
There will, therefore, typically be a plurality of pack- 
ets of data which, when reassembled, constitute the 
entire message that the user entered into the data en- 
try unit 160. These data packets may be temporarily 
stored in the memory unit 170 forfurther processing 
It should be understood, however, that the complete 
message data may be sent as one data packet. Once 
the data packets are formed, the processor 162 re- 
trieves the key. K. from the file 172 and proceeds to 
generate and transmit a signed message for each 
packet of data as explained in greater detail below 
The processor 1 62 also controls the flow of informa- 
tion to and from other components in the wireless de- 
vice 150. 

As shown in step 305. the device 150 computes 
a hashed version of a first data packet by applying a 
pre-defined hashing algorithm to the first data packet 
to form hashed information. The hashing algorithm is 
executed by a hashing unit 161 connected to the proc- 
essor 162. The hashing unit 161 may suitably be an 
electronic circuit which implements the pre-defined 
hashing algorithm. In an alternative embodiment the 
hashing unit 161 may be a processor, such as a gen- 
eral purpose processor programmed with appropriate 
software, which implements the hashing algorithm. 
Such hashing algorithms and implementations there- 
of are well-known in the art and are described, for ex- 
ample, in "Secure Hash Standard." Federal Infonna- 
tion Processing Standard. Publication No. 180/XAB. 
National Bureau of Standards. May 11, 1993. The 
subject matter of this publication and the subject mat- 
ter of all other publications referred to herein are in- 
corporated by reference. 

Next, as shown in step 310 of FIG. 3. the device 
1 50 computes an encrypted version of the hashed in- 
formation according to a primary encryption algo- 
nthm using the private key, K. to form encrypted hash- 
ed information. The encrypted version of the hashed 
information is computed by a primary encryption unit 
1 63 connected to the processor 160. The primary en- 
cryption unit 163 may be an electronic circuit which 
implements the primary encryption algorithm. Acom- 
mercially available AT&T T7000 Data Encryption 
Processor is also suitable for use as the primary en- 
cryption unit 163. The primary encryption algorithm 
may be a DES encryption algorithm or some other 
suitable secure encryption algorithm that may be 
used with the private key. K. The encryption unit 163 
IS connected to the processor 160. for example, by 
control lines 164 which provide control signals to the 
encryption unit 163. Control signals indicate, for ex- 
ample, whether data or the key, K. is to be entered into 
the encryption unit 1 63. Also, data lines 1 65 are used 
to transfer the plain and encrypted data between the 
encryption unit 163 and the processor 160. 

In an alternative embodiment, the encryption unit 
163 may be a processor, such as a general purpose 



processor programmed with appropriate software, 
which encrypts the hashed data according to the pri^ 
mary encryption algorithm. Hardware and software 
implementations of encryption algorithms are well- 
5 known in the art and are described more fully, for ex- 
ample, in -DES Modes of Operation," Federal Infor- 
mation Processing Standard, Publication No. 81, Na- 
tional Bureau of Standards, December 2. 1980,' and 
"Guidelines For Implementing and Using The NBS 
10 Data Encryption Standard." Federal Information 
Processing Standards, Publication No. 74. National 
Bureau of Standards, April 1. 1981. 

The encrypted version of the hashed information 
computed in step 310 is the digital signature referred 
15 to above. The digital signature, therefore, is obtained 
by applying the pre-defined hashing algorithm and 
the primary encryption algorithm to the first data 
packet, where the primary encryption algorithm uses 
the private encryption key, K. Once the device 150 
20 computes the digital signature for the first data pack- 
et, the processor 162 retrieves the identification in- 
formation stored as the ESN 171 as shown in step 
312. This identification infonnatlon is included in the 
segment201 ofthe signed message 200, and thefirst 
25 data packet is included in the segment 203. Next, as 
shown in step 315, the transmitter 155 transmits a 
signed message via the wireless network 140. 

The preferred order for transmitting the three 
segments 201-203 is to place the segment 201 con- 
30 taining the identification information, which prefer- 
ably is of fixed length, at the front of the signed mes- 
sage 200. The segment 203 containing the data pack- 
et, which may be of variable length, is placed at the 
end of the message 200. If, however, the segment 
35 203 is also of fixed length, then it is desirable to trans- 
mit it before the segment 202 containing the digital 
signature. Transmitting segments of fixed length at 
the front of the signed message makes it easier for 
the messaging unit 100 to determine where one seg- 
40 ment ends and another segment begins. Also, placing 
the segment 201 at the front of the signed message 
permits processing at the messaging network 100 to 
take place without unnecessary delay because the 
identification information in the segment 201 is need- 
45 ed to begin processing the received message at the 
messaging network 100. It is to be understood, how- 
ever, that the segments 201-203 may be transmitted 
in any order in accordance with the present invention. 
Also, in a preferred embodiment, the data packet 
50 which is contained in the third segment 203 is also 
transmitted in an encrypted form. After the processor 
1 60 has disassembled the message data into packets 
of data and prior to performing the step 305. the first 
data packet is encrypted using an encryption key, K2. 
55 that differs from the private key. K. For this purpose.' 
a secondary encryption unit 166. connected to the 
processor 160. may be used. The secondary encryp- 
tion unit 166 may be similar to the primary encryption 
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unit 163 and connected to the processor 162 in a sinrv 
ilar manner. The key, K2, may be stored in a file 173 
in the memory unit 170. One purpose of the encryp- 
tion performed by the secondary encryption unit 166 
is to prevent unauthorized persons from intercepting 
the signed message and reading the contents of the 
data packet 

Once the signed message is transmitted via the 
wireless network 140, it is received by the wireless in- 
terface 130 and transmitted to the messaging net- 
work 100, which receives the signed message in the 
receiver 105 as shown in step 320. The recerved sign- 
ed message may be temporarily stored in a file 121 
in a memory unit 119 that is connected to the receiver 
105. 

The memory unit 119 also has a look-up table 120 
which stores the encryption key corresponding to 
each subscriber. The look-up table allows the encryp- 
tion key corresponding to a particular subscriber to be 
retrieved based upon the identification infomnation 
received in the segment 201 of the signed message. 
A processor 112, such as a central processing unit, is 
connected to the memory unit 119 and controls the 
flow of data to and from other units in the messaging 
network 100. In step 325, the processor 112 retrieves 
the encryptton key that corresponds to the identifica- 
tion information contained in the segment 201 of the 
signed message, tf the individual who used the device 
150 to send the signed message is a legitimate sub- 
scriber using a legitimate encryption key and a corre- 
sponding legitimate wireless device, then the key re- 
trieved by the messaging network 1 00 in the step 325 
is the same as the key. K, used by the subscriber to 
transmit the signed message. 

Next, as shown in step 330, the messaging net- 
work 100 computes a hashed version of the data 
packet received in the third segment 203 according to 
the same pre-defined hashing algorithm that was 
used by the device 1 50 in the step 305 to form hashed 
data. Execution of the hashing algorithm in the step 
330 may be performed by a hashing unit 111 connect- 
ed to the processor 112. The hashing unit 111 may 
suitably be an electronic circuit which implements the 
pre-defined hashing algorithm. In an alternative env 
bodiment, the hashing unit 161 may be a processor, 
such as a general purpose processor programmed 
with appropriate software, which implements the 
hashing algorithm. 

Next, in step 335, the messaging network 100 
computes an encrypted version of the hashed data, 
to fonm encrypted hashed data. The encryption key 
retrieved in step 325 and an encryption algorithm are 
used to encrypt the hashed data. The encryption im- 
plemented in step 335 depends upon the key that is 
retrieved from the database 119, which in turn de- 
pends upon the identification information that was re- 
ceived In the first segment 201 of the signed message 
200. If the subscriber and the device 150 are legiti- 



mate, then the encryption algorithm used in the step 
310 and the primary encryptton algorithm used in the 
step 335 are the same. 

An encryption unit 113, which is connected to the 
5 processor 112. executes the encryption algorithm in 
step 335 using the key retrieved from the menriory 
unit 119 according to known techniques in either hard- 
ware or software. The encryption unit 113 may be an 
electronic circuit which implements the primary en- 
10 cryption algorithm. A comn^rcialiy available AT&T 
T7000 Data Encryption Processor is also suitable for 
use as the encryption unit 113. The encryption unit 
113 is connected to the processor 112, for example, 
by control lines 114 which provide control signals to 
15 the encryption unit 113. Control signals indicate, for 
example, whether data or the retrieved key is to be 
entered into the encryption device 163. Also, data 
lines 115 are used to transfer the plain and encrypted 
data between the encryption unit 113 and the proces- 
20 sor112. In an alternative embodiment, the encryption 
unit 113 may be a processor, such as a general pur- 
pose processor programmed with appropriate soft- 
ware, which encrypts the hashed data according to 
the primary encryption algorithm. 
25 In step 340, the messaging network 100 com- 

pares the encrypted hashed data computed by it in 
step 335 to thte digital signature contained in the sec- 
ond segment 202 of the received signed message 
200. Acomparing unit 116, which may be an electron- 
30 ic comparing circuit and which is also connected to 
the processor 112. may be used to perform step 340. 
In an alternative embodiment, the comparing unit 116 
may be a general purpose processor programmed to 
compare the encrypted hashed data to the digital sig- 
35 nature. 

As shown in step 345, the next step depends 
upon the results of the comparison performed in the 
step 340. If the encrypted hashed data computed by 
the messaging network 100 is the same as the re- 
40 ceived digital signature, then the subscriber and de- 
vice 150 are authenticated as legitimate, and the in- 
tegrity of the received data packet is deemed to have 
been preserved during transmission. In step 350, the 
messaging network 100 proceeds to process the data 
45 received in the segment 203. For example, if the es- 
tablished protocol requires that the data packet con- 
tained in the third segment 203 be sent in an encrypt- 
ed form as explained at>ove according to the prefer- 
red embodiment, then the messaging network 100 
50 decrypts the data using a decryption unit 118. con- 
nected to the processor 112. The decryption unit 118 
executes in hardware or software a decryption algo- 
rithm which retrieves the original data that was en- 
crypted by encryption unit 166. The decryption unit 
55 118 may be an electronic circuit or a processor, such 
as a general purpose processor programmed with ap- 
propriate software, which executes the decryption al- 
gorithm. Such decryption algorithms and decryption 
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devices are well-known in the art. A commercially 
available AT&T T7000 Data Encryption Processor is 
also suitable for use as the decryption unit 11 B. 

tf, however, the encrypted hashed data computed 
in the step 335 and the received digital signature are 
not the same, then, as shown in step 355, the mes- 
saging network 100 provides a signal indicating that 
the data packet 200 is rejected. 

Signed messages, incorporating the other data 
packets that were formed by the processor 160 from 
the original message data entered Into the device 
1 50, are also transmitted by the device 150 and proc- 
essed by the network 100 according to the same 
method described in detail above. The network 100 
would then reassemble the data packets to recon- 
struct the complete message originally entered into 
the device 150 by the user. Finally, the messaging 
network 1 00 would process the complete message by 
sending the data to its ultimate destination if, for ex- 
ample, the message is an e-mail message, or by act- 
ing upon it if, for example, the data is a control mes- 
sage to the messaging network 100. 

One advantage of the present invention is that it 
helps prevent fraudulent use of messaging or other 
services employing wireless networks. The present 
invention described above provides a means for iden- 
tifying the entity transmitting data over a wireless 
network. Furthermore, the present invention helps 
ensure that only authorized subscribers use the mes- 
saging network and that only legitimate devices are 
used to transmit messages to the messaging net- 
work. 

Another feature of the present invention is that it 
verifies the integrity of the received data. By verifying 
the integrity of the received data, the present inven- 
tion makes it more difficult for a party to deny having 
transmitted the data that was actually received. Thus, 
for example, when parties transact business via a 
wireless network, the present invention makes It more 
difficult for one of the parties to repudiate the trans- 
action by claiming that the information received was 
not the same as the information sent. 

Other applications and arrangements within the 
spirit and scope of the present invention will be readily 
apparent to persons of ordinary skill in the art. For ex- 
ample, although the present invention has been de- 
scribed in the context of a wireless communication 
system 1 in which a signed message is transmitted by 
the wireless device 150 to the messaging network 
100, the roles of the device 150 and the network 100 
may be reversed. In other words, the messaging net- 
work may serve as the wireless transmitting unit 
which sends a signed message, and the wireless de- 
vice may serve as the wireless receiving unit which 
receives and verifies the signed message. Further- 
more, other devices or system components which 
communicate via a wireless network may be config- 
ured for use in accordance with the present invention. 



The present invention is. therefore, limited only by the 
appended dain^. 

5 Claims 

1 . A wireless communication system comprising: 

a wireless transmitting unit for transmit- 
ting a message via a wireless network, said mes- 
10 sage comprising: 

(a) a first segment Including identification in- 
formation; 

(b) a second segment including a data packet; 
and 

15 (c) a third segment including a digital signa- 

ture obtained by applying a hashing algorithm 
and an encryption algorithm to said data 
packet, where said encryption algorithm uses 
an encryption key corresponding to said iden- 
20 tification information; 

a wireless network; and 

a wireless receiving unit comprising: 

(a) means for receiving said message; 

(b) a memory unit for storing the encryption 
25 key corresponding to said kientif ication infor- 
mation; 

(c) a hashing unit for hashing said data packet 
according to said hashing algorithm to form 
hashed data; 

30 (d) an encryption unit for forming encrypted 

hashed data by appjying said encryption algo- 
rithm to said hashed data using said encryp- 
tion key; 

(e) a comparing unit for comparing said en- 
35 crypted hashed data to said digital signature; 

and 

(f) a processor for controlling the flow of data 
to and from other components in said wireless 
receiving unit. 

40 

2. The system of claim 1 wherein the wireless trans- 
mitting unit comprises: 

(a) a data entry unit for entering message 
data, comprising said data packet, into said 

45 wireless transmitting unit; 

(b) a memory unit for storing said encryption 
key and said identification infomnation; 

(c) a hashing unit for hashing said data packet 
according to said hashing algorithm to form 

50 hashed information; 

(d) an encryption unit for forming said digital 
signature by applying said encryption algo- 
rithm to said hashed Information; and 

(e) a processor for controlling the flow of infor- 
55 mation to and from other components in said 

wireless transmitting unit 

3. The systehi of daim 2 wherein the memory unit 
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of said wireless transmitting unit stores the iden- 
tification infonmation as an electronic serial nunn- 
ber. 

4. The system of claim 3 wherein the memory unit 5 
in said wireless receiving unit stores said encryp- 
tion key in a look-up table. 

5. The system of claim 4 wherein the hashing unit in 

the wireless transmitting unit and the hashing io 
unit in the wireless receiving unit are electronic 
circuits. 

6. The system of claim 4 wherein the encryption unit 

in the wireless transmitting unit and the encryp- is 
tion unit in the wireless receiving unit are elec- 
tronic circuits. 

7. The system of claim 4 wherein said processor is 
programmed to disassemble said message data 20 
into a plurality of data packets. 

8. A method of identifying a user of a wireless conv 
munication system and verifying the integrity of 
data transmitted in said communication system, 25 
said method comprising the steps of: 

sending a message via a wireless net- 
work, where said message comprises: 

(a) a first segment including identification in- 
formation; 30 

(b) a second segment including a data packet; 
and 

(c) a third segment including a digital signa- 
ture obtained by applying a hashing algorithm 

and an encryption algorithm to said data 35 
packet, where said encryption algorithm uses 
a private encryption key; 
receiving said message; 
hashing said data packet according to said 
hashing algorithm to fonn hashed data after per- 40 
forming the step of receiving said message; 

encrypting said hashed data with said en- 
cryption algorithm and said encryption key to 
form encrypted hashed data; and 

comparing said digital signature to the en- 45 
crypted hashed data so as to verify the integrity 
of the data packet. 

9. A method of verifying the integrity of a data pack- 
et transmitted via a wireless communication net- so 
work, said method comprising the steps of: 

hashing the data packet according to a 
hashing algorithm to form hashed information; 

encrypting the hashed information with an 
encryption algorithm using a private encryption 55 
key to form a digital signature; 

retrieving identification information; 

transmitting a signed message via a wire- 



less network; 

receiving said signed message; 

hashing said data packet according to said 
hashing algorithm to form hashed data after per- 
forming the step of receiving said signed mes- 
sage; 

encrypting said hashed data with said en- 
cryption algorithm and said encryption key to 
form encrypted hashed data; and 

comparing said digital signature to the en- 
crypted hashed data so as to verify the integrity 
of the data packeL 

10. A method of sending a message via a wireless 
network, said method comprising the steps of: 

entering message data into a wireless 
transmitting unit; 

disassembling said message data into a 
plurality of data packets; 

perfomning for each data packet the steps 

of. 

(a) hashing the data packet according to a 
hashing algorithm to form hashed informa- 
tion; 

(b) encrypting the hashed information with an 
encryption algorithm using a private encryp- 
tion key to form a digital signature; 

(c) retrieving identification information; 

(d) transmitting a signed message via a wire- 
less network; 

(d) receiving said signed message; 

(e) hashing said data packet according to said 
hashing algorithm to form hashed data after 
performing the step of receiving said signed 
message; 

(f) encrypting said hashed data with said en- 
cryption algorithm and said encryption key to 
form encrypted hashed data; and 

(g) comparing said digital signature to the en- 
crypted hashed data so as to verify the integ- 
rity of the data packet after said message is 
received; and 

reassembling said plurality of data pack- 
ets to reconstruct said message data. 

11. The method of daim 9 or 10 wherein the step of 
transmitting a signed message comprises the 
step of transmitting a message having: 

(a) a first segment including said identifica- 
tion information; 

(b) a second segment including said data 
packet; and 

(c) a third segment including said digital sig- 
nature. 

12. The method of daim 11 wherein the step of trans- 
mitting a signed message further comprises the 
step of sending said first segment at the front of 
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said signed message. 

1 3. The method of daim 8 or 12 further including the 
step of retrieving the encryption key after per- 
forming the step of receiving said message. 

14. The method of daim 13 wherein the step of re- 
trieving the encryption key comprises the step of 
retrieving said encryption key based upon said 
identification information. 



15 



20 



25 



30 



35 



40 



45 



50 



55 



8 



4 ' K 



EP 0 689 316 A2 




g 

Li. 




T 

o 
o 



<D 

E 

CO 

c 

CO 



CM 
CD 



O 

LI 



O 
c/> 

CO 
CD 



CO 



CO 



"cd 
a. 



O 

E 

CD 



CO 



<D 
O 

*> 

o 

CO 
(O 

© 



Q LU 



T 
o 

CO 



x: 




CO 




€0 




X 





in 

CO 



CO 



Q. 

a 
c 
LU 

T" 

CO 
CO 



a. 

o 
c 
Lii 

CO 
CO 



T 

o 
in 



9 



EP0 689 316 A2 



200 



201 



202 



203 



Identification 



Digital Signature 



Data 



FIG. 2 



300 



Enter Message Data 



302 



305 



310 



I 



Disassemble Into 
Data Packets 



I 



Device Computes Hashed 
Version of Data 



I 



312 



Device Computes 
Encrypted Version of 
Hashed Info Using Key 



Retrieve Identification Info 



Device Transmits Signed 
Message Via Wireless 
Netw ork 



315 



355 



320 



Messaging Network 
Receives Signed Message 



325 



Messaging Network 
Retrieves Key Corresponding 
to Identification Info 

I 



330 



Messaging Network 
Computes Hashed 
Version of Data 




335^ 


Messaging Network 
Computes Encrypted 
Version of Hashed Data 
Using Retrieved Key 


340^ 




Messaging Network 
Compares Its Encrypted 
Version of Hashed Data 
to Digital Signature 
Received in Signed Message 





350 



Proceed to 
Process Data 



FIG. 3 



10 



